# Split and store tags

**URL:** <https://discuss.elastic.co/t/split-and-store-tags/275866>\
**Category:** Logstash\
**Created:** [June 14, 2021, 3:53pm UTC](https://discuss.elastic.co/t/split-and-store-tags/275866 "2021-06-14T15:53:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rodrigue](https://avatars.discourse-cdn.com/v4/letter/r/f04885/32.png) [@rodrigue](https://discuss.elastic.co/u/rodrigue)\
**Post date:** [June 14, 2021, 3:53pm UTC](https://discuss.elastic.co/t/split-and-store-tags/275866/1 "2021-06-14T15:53:35Z")

</div>

Hello,  
Sorry to bother you but I tried everything...  
Il simply would like to take tags from my json and store it as a tag in logstash...

Here is my configuration

```auto
input {
    http {
        port => "5046"
        tags => ["log-from-http"]
    }
}

filter {
    if "log-from-http" in [tags] {
        json {
            source => "message"
            target => "logFromHttp"
        }
        mutate {
            remove_field => ["headers"]
        }
        mutate {
            add_tag => ['%{[logFromHttp][tags]}']
        }
    }
}
output {
    if "log-batiimmo-dev" in [tags] {
        file {
            codec => rubydebug
            path => "/home/leopold/tmp/logstash.log"
        }
    }
}

```

I send this json on the http port

```auto
{
    "key1": "value1",
    "key2": "value2",
    "key3": "value3",
    "tags": ["tag1", "tag2"]
}

```

And, in the end my problem is that the tags are concatenated together : (result from file output when I remove the "if")

```auto
tags => [
[0] "log-from-http"
[1] "tag1,tag2"
]

```

What I want to achieve is

```auto
tags => [
 [0] "log-from-http"
 [1] "tag1"
 [2] "tag2"
]

```

Could you please tell me what I'm doing wrong ? (I stried with split, I tries split with terminator=",", nothing works... )

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 14, 2021, 4:11pm UTC](https://discuss.elastic.co/t/split-and-store-tags/275866/2 "2021-06-14T16:11:51Z")

</div>

When you use a sprintf reference the field is converted to a string before it is used. If you want to add each member of the array then use ruby

```
    ruby {
        code => '
            tags = event.get("[logFromHttp][tags]")
            if tags.is_a? Array
                tags.each { |x|
                    event.tag(x)
                }
            end
        '
    }
```

---

<div class="post-metadata">

**Author:** ![rodrigue](https://avatars.discourse-cdn.com/v4/letter/r/f04885/32.png) [@rodrigue](https://discuss.elastic.co/u/rodrigue)\
**Post date:** [June 14, 2021, 5:43pm UTC](https://discuss.elastic.co/t/split-and-store-tags/275866/3 "2021-06-14T17:43:58Z")

</div>

Thanks :)... It works...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2021, 5:44pm UTC](https://discuss.elastic.co/t/split-and-store-tags/275866/4 "2021-07-12T17:44:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
